Relays Are Masking Chinese Access to Frontier AI Models in the US

A sprawling network of intermediary servers has been found to be enabling users in China to access cutting-edge AI models in the US without revealing their identities or location. More than 80,000 “relay” servers, discovered by cybersecurity firm Team Cymru, are allowing operators to pool credentials for multiple AI accounts and route user requests through the servers to frontier services.

These relay servers can undermine the controls that AI providers rely on to detect and restrict misuse. By separating the apparent requester from the actual user, they enable users to bypass potential geographic restrictions and obscure who is accessing models. This allows users to share or resell credentials, as well as evade a provider’s terms of service.

The findings come just days after the US government accused Chinese AI companies of attempting to clone US AI capabilities via systematic distillation campaigns. Team Cymru researcher Scott Fisher explained that relay servers break the assumption every frontier-model control depends on: that the account making a request belongs to the party consuming the answer. This allows for massive-scale fraud, as users can use the relays to mask their identities and access multiple accounts.

Team Cymru initially identified 10,867 transfer stations across 457 autonomous systems, but updated this number after further digging. They found that some of these relay servers were connecting to both Chinese AI providers and Western companies, including Anthropic, OpenAI, Google, and xAI. The researchers observed a high volume of traffic from China and Hong Kong to the relay stations, with over 14TB of data sent in one eight-day period.

The analysis suggests that the traffic is likely related to large-scale model distillation attempts, where attackers use a frontier model’s outputs as training data to develop a cheaper, less capable model. This would enable Chinese users and organizations to create their own versions of advanced AI models at a lower cost than developing them independently. Team Cymru identified two open source software packages that are being used to facilitate this activity.

The widespread use of relay servers to access frontier AI models raises concerns about the security and integrity of these systems. While the findings do not establish how many people are actively using the relays, they point to a significant interest in the technology. As the use of AI continues to grow, it is essential for providers and users to be aware of the potential risks and vulnerabilities associated with these systems.

To stay safe, users should be cautious when sharing or reselling credentials, and ensure that they are complying with the terms of service set by their chosen provider. Additionally, AI providers must remain vigilant in monitoring and detecting misuse, as relay servers can significantly undermine their controls. By taking proactive steps to address these issues, we can better protect our systems from potential threats and maintain the integrity of our advanced technologies.


Source: Dark Reading — 2026-09-22